Recovery Readiness in the AI Era with Clumio

One AI agent can touch a billion Amazon S3 objects in an hour. Poojan Kumar says most recovery architectures were never designed for that kind of scale.

For this Cybersecurity Spotlight session at Six Five Summit: AI Unleashed 2026, Patrick Moorhead speaks with Poojan Kumar, President and CEO of Clumio, a Commvault company, to examine how agentic AI is exposing the limits of traditional backup and recovery at cloud scale.

Kumar argues that backup speed still matters for compliance, but recovery speed is the metric customers actually use to judge cyber readiness. That distinction is becoming more important as AI agents gain the ability to create, modify, or corrupt enormous volumes of data in minutes.

Traditional snapshots and replication can become blunt instruments at cloud scale. Organizations managing billions of objects across S3 buckets or billions of rows in DynamoDB tables may not need to restore an entire bucket or table after an incident. They may need a single prefix, a specific group of objects, or a subset of records—and they need it quickly.

Kumar connects that requirement to the architectural decisions Clumio made from the beginning. Its serverless platform uses AWS Lambda functions and parallelized processing to support fine-grained recovery at scale. He also discusses Clumio's S3 Instant Access capability, which allows applications to resume in minutes through a read-only endpoint while a full restore continues in the background.

For highly regulated industries—including financial services, pharmaceuticals, defense, and government—recovery requirements are also expanding. Cross-region recovery and rigorous compliance postures are becoming baseline expectations rather than advanced features. Clumio's FedRAMP Moderate Ready designation and listing on the FedRAMP Marketplace reflect that shift.

Kumar closes with the question he believes every board should ask its head of IT: not whether an attack will happen, but how quickly the organization can recover when it does.

Key Insights:

🔹 Recovery speed has become the cyber readiness benchmark that matters most at scale. Backup speed still counts for compliance, but Kumar says customers judge readiness on how fast they can recover when something goes wrong.

🔹 Snapshots and replication are too coarse for cloud-native scale. Customers managing billions of objects in S3 or rows in DynamoDB need fine-grained recovery, down to a single prefix, rather than restoring an entire bucket or table.

🔹 Clumio's serverless architecture was built for recovery speed from the start. Its Lambda-based platform enables instant restore, letting applications resume operation while recovery continues in the background.

🔹 Regulated industries are adding cross-region and compliance requirements as standard, not advanced, capabilities. Clumio's FedRAMP moderate marketplace listing reflects that shift for financial services, government, and defense customers.

🔹 The board-level question has changed. Kumar says the right question for any head of IT is no longer whether an attack will happen, but how fast the organization can recover when it does.

Kumar's closing case is direct: as agentic AI compresses the time between a mistake and its consequences, recovery speed stops being a technical metric and becomes the business's actual measure of resilience.

Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.

Check out all of the Six Five Summit: AI Unleashed 2026 content at sixfivemedia.com/summit.

Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.

Poojan Kumar:
Most of our customers, especially at scale, for them the most important metric, while they need the backup speed, for obviously compliance reasons, the recovery speed is their cyber readiness benchmark.

Patrick Moorhead: 

Hey, everybody. Welcome to the Six Five Summit 2026. We are unleashing AI. That is the theme of the summit. But we are unleashing not only the benefits of agentic AI, but if we're doing that, we're also unleashing adversaries on our data. And that is as big a conversation right now as anything that I've seen. It seems like people are finally waking up to this. And we're going to talk about how AI is changing the way that organizations really should be thinking about cyber resilience. Not only is agentic AI giving amazing outcomes, it's also creating more types of data and also bifurcating the workloads across different areas of the ecosystem. And joining me right now is Poojan Kumar, President and CEO of Clumio. kind of go through how enterprises, organizations, governments can build greater confidence in their ability to recover in today's AI and cloud-first world. Welcome back to The Six Five. Thank you, Patrick. Happy to be here. Excellent. So AI is changing everything. It's hard to believe that we've only been, I don't know, back in this game three and a half, almost four years. But one thing that's first and foremost, I was actually in the original announcement with Sam Altman and Satya Nadella. First thing that hit me is, How is this going to change how we look at enterprise data? And aside from doing the recipes that they did three and a half years ago, the enterprise value prop is different. And as we see more organizations moving from this experimentation to pilots to production, the ability to trust and recover that data becomes, quite frankly, I'll call it a boardroom discussion, not just an IT issue. Why has recovery readiness become so important in this agentic AI era? Absolutely.

Poojan Kumar: 

I think if you think about it, it was always important, right? You know, the most, you know, crown jewel for every or any organization out there has been the data, right? That the data basically that the customer data, they have their own data that they house and so on and so forth. But with AI now, both, you know, with more and more enterprises writing, you know, AI agents and AI applications, the speed of change has become very rapid. So now basically, you know, all of these, you know, AI applications have been written, AI agents, you know, on top of the data that you're on. And, you know, with all the changes that are happening, if you ever, you know, if an agent goes rogue, if a mistake happens or whatever, you know, previously, you could catch it in time. In fact, you might have had time to recover also. But now these applications are also no longer test and dev. Even if it's internal, it's going to thousands of users. If it's external, it's probably tens of thousands of users or more. And so now you need the ability to go recover them rapidly also. And the amount of data that they could touch is a lot in a short amount of time. So that's where What also matters is, can you go and process, you know, the recovery at the speed at which, you know, the application was getting processed to begin with, right? So the recovery processing and the data processing for recovery, the speed becomes very, very important.

Patrick Moorhead: 

Yeah, we have. moved far along from the days of perimeter defense, and then we moved into, okay, you're going to get in quickly, we're going to get you out, which then moved into the, okay, you're going to get in, we're not going to be able to get you out quickly enough, but we're going to protect your data. But now we're operating at machine speed, which is fundamentally different here. And a lot of organizations think snapshots, replication or native cloud capabilities where they're doing a ton of backups, provides everything that they need in this new agentic light speed era. But cloud environments are getting a lot more complex. Applications are becoming more fractalized. That assumption that snapshots replication and cloud capabilities alone is being challenged. Talk us through why do these modern cloud workloads require a different approach to resilience?

Poojan Kumar: 

Absolutely. I think if you think about it, right, it's like some of these capabilities like, you know, snapshotting and application are just, you know, pure building blocks, right? So they really protect you at a more fundamental level. But if you think about applications that are written in the cloud, especially, and using, you know, workloads and services like, you know, in Amazon S3 or Amazon DynamoDB or the equivalence of that in other hyperscaler environments, these applications are written at massive scale. We have customers who have billions of rows in their DynamoDB tables, have billions of objects. in their S3 environment. This is tens of petabytes, and so on and so forth. So now, when you're doing things at that scale, and now unleashing agents on top of it, the changes are pretty rapid. Essentially, in an hour, you could be adding a billion more rows. In an hour, you could be touching a few billion S3 objects. So when that happens, you cannot rely on that fundamental building block, which is the snapshots and replication. They are too coarse. And so you need to get more fine grain so that you can essentially go and tackle and say, OK, I touched that 1 billion object across my 10 billion. And how do I go and quickly, quickly is the important word, quickly go and recover it if needed. Same thing for objects out there. So that becomes important. And the fundamental building blocks, while important for huge catastrophes or whatever, are essentially there, but not really relevant as you think about these scales.

Patrick Moorhead: 

Yeah. And it seems like before this era, backup was really the benchmark But now, given the light speed and the fact that you can take down your entire operations, people are starting to think through this beyond just storing another copy of that data. So is recovery really the new metric that should be defining a higher level of cyber resilience that just doesn't, back up the data, but finds a way to get you up and operational quickly.

Poojan Kumar: 

This is a key point. When we built Chromio more than seven, eight years ago, we built an architecture that was based off a serverless architecture, a Lambda-based architecture. So that did two things. One is it allowed you to essentially protect your environment, backup your environment. So meet your SLAs. Obviously you had to comply and have a certain SLA. Okay. For these buckets and these, you know, VMs, I need a four, a four hour RTO. And in this case, I need an eight hour and so on and so forth. So you needed the speed to make sure you're, you're hitting your SLAs. You get your check boxes for compliance reasons. But then the same architecture also was important for us to go and essentially say, can I also do recovery at blazing speeds? So we built that from day one. I could essentially spawn off thousands of lambdas and recover your environment at blazing speeds. And that, early on, was becoming a performance metric. Oh, you can recover. That's awesome. I don't know if it's important to me. But fast forward now. Most of our customers, when they run a POC with Clumio, for them, the key criteria is the recovery speed, especially in the AI era we are in. And basically what they're essentially saying is if you cannot recover for me, at this particular, at this pace, and especially in the age of AI becoming malicious or ransomware attacks being used with AI and so on and so forth, and in which case, too much might have happened before you realize that something bad has happened. So the recovery speed, if you do not achieve those speeds, that creates a business risk, because these are business customer-facing applications. So most of our customers, especially at scale, for them, the most important metric, while they need the backup speed, for obviously compliance reasons, the recovery speed is their cyber readiness benchmark.

Patrick Moorhead: 

Yeah, and that makes a lot of sense. And if you look at the, call it the traditional enterprise, even though there is not anything such as traditional enterprise, they're all different, but they have a collection of different types of applications, right? They've got homegrown, on-prem, colo, and then they have even some of those types of applications that they redeploy to the cloud. And then you have cloud native applications, like you would think, because cloud native applications are, I guess we can argue, a decade, might be the oldest one. Even though if you're using things like functions or something like that, they're newer, but as they continue to grow in scale and complexity, older architectures weren't designed for this operating model. And the enterprises that we're talking to, and I'm sure you are looking ways to improve, have their cake and eat it too. How do I improve my resiliency without adding a tremendous amount of operational burden as it as I'm cutting across all of these, I've heard you say that your cloud native architecture changes the recovery experience across this complexity. Can you talk through us a little bit, give us some specifics?

Poojan Kumar: 

Absolutely, I think there's a lot of things that go into this. I'll give you a couple of concrete examples. So essentially when somebody is going and recovering massive environments, it's about going and recognizing for them exactly what needs to be recovered. Sometimes they know, sometimes they don't know. going and essentially be able to essentially go and partition their data and go and recover sometimes in place, maybe sometimes out of place, exactly that prefix, right? It's like, oh, I could have this, you know, massive S3 bucket and bunch of prefixes in the S3 bucket, but I only need, I know my agent went and messed up only that prefix and I need to go and only recover the objects within that prefix. So you need to go build a solution that not only scales and essentially partitions all of the objects and really goes and quickly recovers them but also goes and does it at fine granularities like prefixes, whether it's a DynamoDB table or S3 bucket and so on and so forth. And then there's other things where can my application and can my agent from a recovery perspective, do I need to wait for the entire recovery to complete? Or can I essentially go start working and get, you know, go live? ASAP, which is where we provide capabilities like instant restore, where you start your recovery and essentially your application can start. And if you bump into an object that I've not recovered yet, that's okay. I will go and quickly recover that one for you because you asked for that object. So things like that, you have to go and build because that increases the speed of recovery virtually effectively. And also it essentially allows somebody to go get up and running really fast.

Patrick Moorhead:

Yeah, that's definitely having your cake and eat it too. That's exciting. It's exciting stuff. Hey, I want to shift to highly regulated industries, financial, pharma, defense, government, critical infrastructure. they've been holding back a bit on, you know, and they might have 20,000 applications moving toward a cloud native architecture. And at the same time, their resilience requirements are understandably higher, which is, you know, one of the reasons most of them have stayed on-prem, at least in their belief that more highly regulated, they can't be turned off and they have control. But as you look at that market today, the highly regulated industries and your customers, where are you seeing the biggest shift in the expectations and their requirements?

Poojan Kumar: 

No, I think these highly regulated environments obviously have the next level of requirement. Obviously, you need the speed and all the functionality features I talked about, but then you need other constructs on top of it. Like, OK, I have this in this region. I need to be able to make sure that I have a copy of this in the other region, and my application can go restart at the other region, so the data better be available at the other region. So the cross-region capabilities and stuff like that become very important. while again maintaining the requirements of speed and recovery time and so on and so forth. The other thing that a lot of these regulated environments require is in things like FedRAMP. So we recently, Clumio, we announced our FedRAMP moderate marketplace listing. So essentially the highly regulated environments can essentially go and use the solution even for the highly regulated environments. So things like that. So we're continuously going and working with these industries and providing them the functionality that they need so that essentially they can go operate at peace.

Patrick Moorhead: I want to ask you one final question here. So Poojan, you're on the board of Clumio, and you've been on a bunch of other boards. I present to boards, been on some public boards, but not served on a public board before. they are asking, what would your advice be to be the number one question that they should ask their head of IT?

Poojan Kumar: 

Yeah, so I think this is something that, you know, ironically, we had talked about even a few years ago, when we were having a conversation, I can't name the other company that we were talking about in the context of a public company. But for both these, we are a smaller private company, and the other one is a public company. And the question that was asked, like, okay, whether it's that one, or you guys, the what is your biggest threat today and the biggest threat essentially was what if I get hit by you know ransomware and I think about it like we're basically sitting with customers data in a sitting in our tenant and so on and so forth so if you get hit you're exposing a lot of your customers. So that is the number one question. It's not like, oh, person X leaves, person Y leaves, a key employee, so on and so forth. Obviously, all those things are important. But the key thing is, how are you protected in the event of an attack? And in most cases, it's a question of, not if, it's a question of when, and when that happens, are you ready? Are you ready to essentially go and be able to recover your business?

Patrick Moorhead: 

Listen, those are sage words for senior executives who need to make sure that security and resiliency aren't the job of IT anymore. And I've seen a lot of movement on boards, but I think we are in a different area here in agentic AI. Poojan, thank you so much for joining this cybersecurity spotlight session. I really do appreciate it. Thank you, Patrick. Enjoyed it.

Poojan Kumar: 

Looking forward to the next one with you.

Patrick Moorhead: 

All right, folks. Unleashing AI, the benefits of it, but also the risks that enterprises need to take in account, plan for, and invest for. To our viewers, subscribe, follow us on social media, check out all of our Six Five Summit content on our website. See you next time.

Speaker

Poojan Kumar
Chief Product Innovation Officer
Commvault

Poojan Kumar, Commvault’s Chief Product Innovation Officer, leads the company’s innovative product development strategy for today’s cloud-first, data-driven world.

An engineering visionary, Poojan re-envisioned how data is managed, analyzed, stored, and recovered at companies including Nutanix, VMware, and Oracle. And as an entrepreneur, he built, scaled, and led the acquisition of multiple successful companies. Most recently, he co-founded and was CEO of Clumio, which Commvault acquired in 2024.

Poojan earned his bachelor’s in computer science at the Indian Institute of Technology and his master’s in computer science from Stanford University.

Poojan Kumar
Chief Product Innovation Officer